๐ต๐ฑ
sefinek.net
2026-07-20 18:48:33
(1 hour ago)
Triggered Cloudflare WAF (firewallCustom) from ZW.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (P ...
show more
Triggered Cloudflare WAF (firewallCustom) from ZW.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (POST) | Endpoint: /xmlrpc.php | UA: Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ช๐ธ
masterguru
2026-07-20 16:35:02
(4 hours ago)
(xmlrpc) Failed xmlrpc access from 197.221.254.99 (ZW/Zimbabwe/16.99.telone.co.zw): 5 in the last 36 ...
show more
(xmlrpc) Failed xmlrpc access from 197.221.254.99 (ZW/Zimbabwe/16.99.telone.co.zw): 5 in the last 3600 secs (0-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-20 11:50:17
(8 hours ago)
(mod_security) mod_security (id:240335) triggered by 197.221.254.99 (16.99.telone.co.zw): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 197.221.254.99 (16.99.telone.co.zw): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 07:50:10.947701 2026] [security2:error] [pid 32072:tid 32189] [client 197.221.254.99:31278] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.221.254.99 (+1 hits since last alert)|reghay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "reghay.com"] [uri "/xmlrpc.php"] [unique_id "al4LctzyvRTlgUtQeJHMqAAAAcU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-20 10:48:12
(9 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฒ๐พ
Rizzy
2026-07-20 08:44:58
(11 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
Kenshin869
2026-07-20 05:00:23
(15 hours ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-20 03:21:19
(17 hours ago)
(mod_security) mod_security (id:240335) triggered by 197.221.254.99 (16.99.telone.co.zw): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 197.221.254.99 (16.99.telone.co.zw): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 23:21:13.207434 2026] [security2:error] [pid 23217:tid 23217] [client 197.221.254.99:34713] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.221.254.99 (+1 hits since last alert)|edmestonfd.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "edmestonfd.com"] [uri "/xmlrpc.php"] [unique_id "al2UKTUvYyLLlJ4SqRKR3gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-07-19 23:50:24
(20 hours ago)
197.221.254.99 - - [20/Jul/2026:07:45:06 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5867 "-" "Jetpack by ...
show more
197.221.254.99 - - [20/Jul/2026:07:45:06 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5867 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
197.221.254.99 - - [20/Jul/2026:07:50:13 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5867 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
197.221.254.99 - - [20/Jul/2026:07:50:23 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5867 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
๐บ๐ธ
WeekendWeb
2026-07-19 23:45:50
(20 hours ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 16:26:40
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 197.221.254.99 (16.99.telone.co.zw): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 197.221.254.99 (16.99.telone.co.zw): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 12:26:34.275831 2026] [security2:error] [pid 29195:tid 29195] [client 197.221.254.99:53290] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.221.254.99 (+1 hits since last alert)|jimrichardart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jimrichardart.com"] [uri "/xmlrpc.php"] [unique_id "alz6umfX2R9ZhEPN4IvQ4gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-07-19 14:10:07
(1 day ago)
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-19 13:50:28
(1 day ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-19 13:39:58
(1 day ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 12:10:56
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 197.221.254.99 (16.99.telone.co.zw): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 197.221.254.99 (16.99.telone.co.zw): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 08:10:49.183731 2026] [security2:error] [pid 6766:tid 6766] [client 197.221.254.99:32817] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.221.254.99 (+1 hits since last alert)|christaylorjazzpianist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "christaylorjazzpianist.com"] [uri "/xmlrpc.php"] [unique_id "aly-yeYZfRnoRYF3dWkq6wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 11:28:15
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 197.221.254.99 (16.99.telone.co.zw): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 197.221.254.99 (16.99.telone.co.zw): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 07:28:08.318357 2026] [security2:error] [pid 28538:tid 28538] [client 197.221.254.99:15799] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.221.254.99 (+1 hits since last alert)|medusakenya.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "medusakenya.com"] [uri "/xmlrpc.php"] [unique_id "aly0yLqt388UkXctoIt-mAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack